CVE-2020-12283
CVE-2020-12283
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/sourcegraph/sourcegraph/blob/master/CHANGELOG.mdhttps://github.com/sourcegraph/sourcegraph/commit/c0f48172e815c7f66471a38f0a06d1fc32a77a64https://github.com/sourcegraph/sourcegraph/compare/v3.15.0...v3.15.1https://github.com/sourcegraph/sourcegraph/pull/10167https://securitylab.github.com/advisories/GHSL-2020-085-sourcegraph